Skip to content

Enforce dependency edge ownership across Braid - #92

Merged
srinji-kaggss merged 1 commit into
mainfrom
fix/dependency-edge-ownership
Aug 30, 2026
Merged

srinji-kaggss merged 1 commit into
mainfrom
fix/dependency-edge-ownership

Conversation

@srinji-kaggss

Copy link
Copy Markdown
Owner

Dependency authority belongs to direct authored edges, not the accidental transitive lockfile closure.

The old gate warned about roughly 100 transitive packages from one build script while being unable to name the workspace crate that created an edge. Enforcement was stood down, direct serde/serde_json/proptest/tempfile bypasses remained, and copied foreign workspace crates were indistinguishable from local authority.

This change makes cargo metadata --no-deps the source of direct-edge truth. Every approval now records its owning crate, semantic capability, exact manifest requirement, source class, allowed consumers, and allowed dependency kinds. The register is enforced. Unowned edges, wrong consumers, requirement/source/kind drift, copied foreign workspace members, and stale approvals refuse.

The crate graph now follows the same contract:

  • JSON and serde use flow through lgwks_std; the no-std capability token retains one explicit boundary.
  • Property testing flows through the new test-only braid-test-support crate.
  • braid-integrate no longer declares serde, serde_json, or tempfile directly.
  • The same lgwks-gate check . command is lane 4 locally and the first GitHub build gate.

I rejected expanding APPROVED.toml into a transitive whitelist. Cargo.lock remains exact byte provenance; it does not grant package-level authority.

Real paths:

$ cargo run --locked -p lgwks_std_gate --bin lgwks-gate -- check .
OK  . — 12 semantic approvals, every authored external edge is owned

$ cargo test -p lgwks_std_gate copied_foreign_workspace_member_is_refused
test tests::copied_foreign_workspace_member_is_refused ... ok

Regression coverage includes inactive optional/dev metadata edges, unregistered path copies, foreign Braid workspace copies, registry-to-Git drift, wrong consumers, and approvals that outlive their owner edge.

Local CI is green across all 28 lanes for exact SHA 2cd10d953093502bb91532a910b423d2c97b951f; receipt: /Users/srinji/wwfd/state/local-ci-receipt.json.

Closes #91.

Still not done: issue #75 must publish the crate family before issue #76 can migrate external consumers without path or floating-Git fallbacks. The constellation census remains the ordered migration ledger for those follow-up PRs.

@srinji-kaggss
srinji-kaggss merged commit 6d77e71 into main Aug 30, 2026
14 checks passed
@srinji-kaggss
srinji-kaggss deleted the fix/dependency-edge-ownership branch August 30, 2026 17:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

P0: Enforce dependency edge ownership, not a flat lockfile whitelist

1 participant